CVE-2026-42822Disclosure(microsoft / azure_local)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft azure_local systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_local
  • azure_resource_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 5 mentions (2026-05-18); latest day: 2
  • 12 total mentions across 3 days

Affected systems

Vendors
Products
azure_localazure_resource_manager

1 version affected across 2 products

Deep dive

Activity timeline12 mentions / 3d
01345Mentions · 2026-05-18: 5Mentions · 2026-05-19: 5Mentions · 2026-05-21: 2Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-05-18: 3Patch / Workaround · 2026-05-19: 2Technical Details · 2026-05-18: 4Technical Details · 2026-05-19: 3Technical Details · 2026-05-21: 205-1805-1905-21
Signal classification3 categories
Disclosure
650.0%
Patch
541.7%
Active Exploitation
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-185
Disclosure2Patch3
2026-05-195
Active Exploitation1Disclosure2Patch2
2026-05-212
Disclosure2
Full discourse12 posts
  • moto_sato@58_158_177_102
    Disclosure

    Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability Impact Elevation of Privilege Max Severity Critical Metrics CVSS:3.1 10.0 / 8.7 Exploitability assessment Exploitation More Likely https://msrc.microsoft.com/update-guide/ja-jp/vulnerability/CVE-2026-42822

    Post summary

    Microsoft announced a critical elevation‑of‑privilege vulnerability (CVE‑2026‑42822) in Azure Local Disconnected Operations, noting high CVSS scores and likelihood of exploitation, but it does not provide PoC, exploit code, or a patch.

    020541.0K
    9.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-42822 — CVSS 10/10 ██████████ Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/RWOSdyQFLZ

    Post summary

    A critical Azure Local Disconnected Operations auth flaw (CVE‑2026‑42822) with a CVSS score of 10/10 is disclosed; a patch has already been issued and is recommended to be applied.

    10020183
    69 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 5.18 Azure Local 向けディスコネクテッド オペレーション サービスの特権昇格の脆弱性 CVE-2026-42822 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822

    Post summary

    The post announces the discovery of a new privilege escalation vulnerability (CVE-2026-42822) affecting Azure Local disconnected operation services, with reference to Microsoft's advisory.

    10100110
    85 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-42822 | Microsoft Azure Local/Azure Resource Manager improper authentication https://ift.tt/uO6pJHw A vulnerability categorized as critical has been discovered in Microsoft Azure Local and Azure Resource Manager. This affects an unknown part. Executing a manipulation …

    Post summary

    CVE‑2026‑42822 is a newly discovered critical vulnerability in Microsoft Azure Local and Azure Resource Manager due to improper authentication. The brief post references a link but offers no PoC, exploit code, active exploitation evidence, or patch details.

    01010118
    974 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical- Azure Local Disconnected Operations Elevation of Privilege (CVE-2026-42822) A critical Elevation of Privilege (EoP) vulnerability exists in Azure Local Disconnected Operations (ALDO), Microsoft’s hybrid solution for running cloud services in fully disconnected infrastructure. While environments managed directly by Microsoft-operated Azure Resource Manager are fully mitigated, local or air-gapped ALDO control planes remain highly vulnerable to local privilege escalation and infrastructure compromise. 👉 Affected: Azure Local Disconnected Operations (ALDO) deployments < 2604 | Upgrade to ALDO version 2604 or later via full system update

    Post summary

    Microsoft identified a critical elevation‑of‑privilege vulnerability in Azure Local Disconnected Operations and urges customers to upgrade to version 2604 or later.

    00010106
    196 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-42822 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 10.0 / 8.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性が高い https://x.com/kawn2020/status/2057400966736146434

    Post summary

    The tweet announces a Microsoft CVE (CVE‑2026‑42822) for privilege escalation with emergency severity, a CVSS of 10.0/8.7, and high exploitability, but no public exploits, patches, or PoC are referenced.

    0000048
    85 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Azure Local Disconnected Operations Elevation of Privilege Vulnerability CVE-2026-42822 is critical (CVSS 10.0) - Remediation requires upgrading ALDO systems to version 2604 or later via a full system update. #ThreatIntel ... https://hubs.li/Q04h9sW40

    Post summary

    The advisory announces CVE-2026-42822 as a critical elevation-of-privilege flaw with a CVSS score of 10.0, recommending a system update to version 2604 or later as the patch.

    0000075
    2.2K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-42822 scores CVSS 10.0 due to improper authentication in Azure Local Disconnected Operations, allowing network-based privilege elevation. If your environment uses this feature, review the vendor advisory and confirm patching or compensating controls. http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability

    Post summary

    CVE-2026-42822 is a high severity privilege‑elevation flaw in Azure Local Disconnected Operations; the text emphasizes reviewing vendor advisories and applying patches or compensating controls.

    0000049
    80 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-42822 | Microsoft Azure Local/Azure Resource Manager improper authentication (EUVD-2026-30787) https://ift.tt/uO6pJHw A vulnerability categorized as critical has been discovered in Microsoft Azure Local and Azure Resource Manager. This affects an unknown part. Executi…

    Post summary

    A new critical Azure Local/Azure Resource Manager authentication vulnerability (CVE-2026-42822) has been disclosed, but the post offers limited technical detail and no evidence of active exploitation or available patch.

    0000058
    974 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Microsoft Azure Local and Azure Resource Manager (CVE-2026-42822) https://vuldb.com/vuln/364499/cti

    Post summary

    The post notes that multiple actors have increased activity targeting CVE‑2026‑42822, implying potential active exploitation, but it lacks specific PoC, exploit code, or mitigation details.

    0000083
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42822 Privilege Escalation via Improper Authentication in Azure Local Disconnected Operations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42822

    Post summary

    The post announces CVE‑2026‑42822 as a new privilege‑escalation vulnerability affecting Azure Local Disconnected Operations; no PoC, exploit, or patch is provided.

    0000072
    4.0K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Microsoft: “Azure is safe, just not the disconnected Azure.” CVE-2026-42822 proves the edge is where the patch party happens. If you’re offline, you’re still vulnerable. #Windows #Security https://windowsforum.com/threads/cve-2026-42822-aldo-fix-update-to-aldo-2604-or-later-for-disconnected-azure.418796/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #SecurityUpdate #Cve202642822 #AzureLocalDisconnectedOperations https://t.co/XHZoBws2SP

    Post summary

    The post notes a CVE affecting Azure’s disconnected environments and recommends upgrading to aldo-2604 or later, indicating that a patch is available.

    0000090
    1.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_local---
Appmicrosoftazure_resource_manager---

Explore more